Home Cyber Security Discovering the legendary BlackLotus bootkit

Discovering the legendary BlackLotus bootkit

0
Discovering the legendary BlackLotus bootkit

[ad_1]

ESET Analysis

Here is a narrative of how an evaluation of a supposed recreation cheat changed into the invention of a strong UEFI menace

ESET Research Podcast: Finding the mythical BlackLotus bootkit

In the direction of the tip of 2022 an unknown menace actor boasted on an underground discussion board that they’d created a brand new and highly effective UEFI bootkit referred to as BlackLotus. Its most distinctive function? It might bypass UEFI Safe Boot – a function constructed into all trendy computer systems to forestall them from operating unauthorized software program.

What at first gave the impression of a delusion – particularly on a totally up to date Home windows 11 system – has changed into actuality just a few months later, when ESET researchers discovered a pattern that completely matched this fundamental function in addition to all different attributes of the marketed bootkit.

On this episode of ESET Analysis podcast, ESET Distinguished Researcher and host of this podcast Aryeh Goretsky talks to ESET Malware Researcher Martin Smolár about how he found the menace and what the primary findings of his evaluation had been.

Within the dialogue, Martin reveals that he initially thought of the BlackLotus pattern to be a recreation cheat and describes the second when he realized that he had discovered one thing rather more harmful. To keep away from a typical false impression, Martin additionally explains the distinction between malicious UEFI firmware implants and threats that “solely” goal the EFI partition. To make the knowledge actionable for our listeners, the ultimate a part of the dialogue explores the prevention and mitigation of UEFI assaults.

For extra particulars equivalent to who is likely to be affected by BlackLotus or how a menace actor may get hold of the bootkit, take heed to the entire episode of ESET Analysis podcast on Spotify, Google Podcasts, Apple Podcasts, or PodBean. And should you like what you hear, subscribe for extra.

[ad_2]

LEAVE A REPLY

Please enter your comment!
Please enter your name here